All Apps and Add-ons

How to perform a query on the HF that will allow me to then send the data I return to a DB?

dfurtaw
Path Finder

Hi Splunk Answer guys/gals,

I have a question regarding DBConnect and I was curious if anyone had any insight on it. After reading the documentation, I'm still a bit unsure on how to use the DB Output feature that is included in dbconnect. I have dbconnect installed on one of our HF's but in order for the output command to work, I'll need to search the data that is in our Splunk Cloud instance. 

The HF is currently configured to send data to the indexers, but I'm stuck on figuring out how I'll be able to perform a query on the HF that will allow me to then send the data I return to a DB. Currently, I'm unable to pull any data on the HF.

Thank you!

DFurtaw

Labels (1)
0 Karma
1 Solution

chli_splunk
Splunk Employee
Splunk Employee

Unlike DBX input, DBX output is a custom search command to export data from Splunk search results to DB. So it has to run on search head rather than HF. In your case, I'm afraid you have to install DBX on search head, configure it and run DBX output like a search command.

View solution in original post

chli_splunk
Splunk Employee
Splunk Employee

Unlike DBX input, DBX output is a custom search command to export data from Splunk search results to DB. So it has to run on search head rather than HF. In your case, I'm afraid you have to install DBX on search head, configure it and run DBX output like a search command.

richgalloway
SplunkTrust
SplunkTrust
For Splunk Cloud, you need to configure Hybrid Search so your local search head (which can be the HF) can fetch data from Cloud indexers.
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...